# Top

**URL:** https://discuss.elastic.co/top.md?page=23&period=all

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 24

---

## [ElasticSearch crashing - Magento 2.4.3](https://discuss.elastic.co/t/elasticsearch-crashing-magento-2-4-3/284228)

<div class="topic-metadata">

**Author:** [@pmono](https://discuss.elastic.co/u/pmono)\
**Replies:** 24\
**Last updated:** [September 27, 2021, 4:42pm UTC](https://discuss.elastic.co/t/elasticsearch-crashing-magento-2-4-3/284228 "2021-09-27T16:42:39Z")

</div>

We're having issues with Elasticsearch crashing from time to time. It also sometimes spikes up RAM + CPU and server becomes unresponsive. We have left most of the settings as is, but had to add more RAM to JVM heap (48G…

---

## [Sending Attachments: Unexpected end-of-input in VALUE\_STRING](https://discuss.elastic.co/t/sending-attachments-unexpected-end-of-input-in-value-string/9302)

<div class="topic-metadata">

**Author:** [@cocowalla](https://discuss.elastic.co/u/cocowalla)\
**Replies:** 19\
**Last updated:** [October 24, 2012, 7:47am UTC](https://discuss.elastic.co/t/sending-attachments-unexpected-end-of-input-in-value-string/9302 "2012-10-24T07:47:53Z")

</div>

I'm running on Windows, and using Cygwin I've been trying the attachment tutorial, and have tried using the supplied example script . Everything is fine up until: curl -X POST "${host}/test/attachment/" -d @js…

---

## [Massive queue in "refresh" thread pool on a single node, causing timeouts](https://discuss.elastic.co/t/massive-queue-in-refresh-thread-pool-on-a-single-node-causing-timeouts/280732)

<div class="topic-metadata">

**Author:** [@BradVido](https://discuss.elastic.co/u/BradVido)\
**Replies:** 18\
**Last updated:** [September 21, 2021, 10:34am UTC](https://discuss.elastic.co/t/massive-queue-in-refresh-thread-pool-on-a-single-node-causing-timeouts/280732 "2021-09-21T10:34:03Z")

</div>

This is a difficult one because it only happens randomly, I can't figure out a way to reproduce it consistently. What happens is I'll notice a lot of timeouts trying to index to the cluster, and what I've found that s…

---

## [Configure deprecation log index properties](https://discuss.elastic.co/t/configure-deprecation-log-index-properties/291342)

<div class="topic-metadata">

**Author:** [@OrangeDog](https://discuss.elastic.co/u/OrangeDog)\
**Replies:** 9\
**Last updated:** [February 18, 2022, 8:03am UTC](https://discuss.elastic.co/t/configure-deprecation-log-index-properties/291342 "2022-02-18T08:03:17Z")

</div>

7.16 adds a new stream/index for deprecation logging. e.g. the first one today is .ds-.logs-deprecation.elasticsearch-default-2021.12.09-000001 However, it is created with "number\_of\_replicas": "1" and I only have one …

---

## [Logstash \_grokparsefailure error](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989)

<div class="topic-metadata">

**Author:** [@sslv](https://discuss.elastic.co/u/sslv)\
**Replies:** 20\
**Last updated:** [June 21, 2017, 5:31am UTC](https://discuss.elastic.co/t/logstash--grokparsefailure-error/89989 "2017-06-21T05:31:48Z")

</div>

Hi, I am trying to parse a simple log file to understand how logstash works. This is my log format: 2017-06-14 11:17:48 \[ad8880\] INFO: blah blah blah And I have built the following grok regex using grok Constructor %…

---

## [Custom JDK for Logstash](https://discuss.elastic.co/t/custom-jdk-for-logstash/124422)

<div class="topic-metadata">

**Author:** [@qube](https://discuss.elastic.co/u/qube)\
**Replies:** 10\
**Last updated:** [March 20, 2018, 3:01pm UTC](https://discuss.elastic.co/t/custom-jdk-for-logstash/124422 "2018-03-20T15:01:49Z")

</div>

Hello! According to this answer, I extracted the exe file (I'm windows user) and copied the necessary files. For Elasticsearch, it worked. I set java\_home variable in the elasticsearch.bat set JAVA\_HOME=path/to/jdk/fil…

---

## [How to index a file with elasticsearch 5.5.1](https://discuss.elastic.co/t/how-to-index-a-file-with-elasticsearch-5-5-1/95657)

<div class="topic-metadata">

**Author:** [@bilpor](https://discuss.elastic.co/u/bilpor)\
**Replies:** 21\
**Last updated:** [August 4, 2017, 10:45am UTC](https://discuss.elastic.co/t/how-to-index-a-file-with-elasticsearch-5-5-1/95657 "2017-08-04T10:45:42Z")

</div>

I’m new to Elasticsearch. I have successfully installed Elasticsearch with Kibana, X-pack and ingest-attachment. I have both Elasticsearch and Kibana running. I have kept it simple at the moment with the install using de…

---

## [Logstash filter debugging workflow](https://discuss.elastic.co/t/logstash-filter-debugging-workflow/108632)

<div class="topic-metadata">

**Author:** [@ajhstn](https://discuss.elastic.co/u/ajhstn)\
**Replies:** 10\
**Last updated:** [November 27, 2017, 8:02pm UTC](https://discuss.elastic.co/t/logstash-filter-debugging-workflow/108632 "2017-11-27T20:02:47Z")

</div>

hello, how does one test {filters} quickly making small iterative changes to the .conf file and seeing results? Eg my current workflow is open the .conf file, make a change, save it, restart logstash, wait for a matchin…

---

## [Elastic can not start because of memory issue](https://discuss.elastic.co/t/elastic-can-not-start-because-of-memory-issue/282711)

<div class="topic-metadata">

**Author:** [@Vladimir](https://discuss.elastic.co/u/Vladimir)\
**Replies:** 15\
**Last updated:** [August 31, 2021, 1:41pm UTC](https://discuss.elastic.co/t/elastic-can-not-start-because-of-memory-issue/282711 "2021-08-31T13:41:57Z")

</div>

Hi there, can somebody tell me please why my Elastic installation dont want to start? Log says it is out of memory. But it should contains only one index with about one million items. The server params are: 6vCPU, 16G RA…

---

## [SAML settings on elasticsearch and kibana](https://discuss.elastic.co/t/saml-settings-on-elasticsearch-and-kibana/236158)

<div class="topic-metadata">

**Author:** [@Muhammad\_Umair\_Baig](https://discuss.elastic.co/u/Muhammad_Umair_Baig)\
**Replies:** 32\
**Last updated:** [June 22, 2020, 11:36am UTC](https://discuss.elastic.co/t/saml-settings-on-elasticsearch-and-kibana/236158 "2020-06-22T11:36:42Z")

</div>

Hi Guys, i am using kibana and elasticsearch version 7.6.2 free version and trying to enable SAML 2.0 on elasticsearch and kibana. Mentioned below are the configuration files that i am using: elasticsearch log trace: \[…

---

## [Logstash Sourceloader - No configuration found in the configured sources](https://discuss.elastic.co/t/logstash-sourceloader-no-configuration-found-in-the-configured-sources/138441)

<div class="topic-metadata">

**Author:** [@Pixarjunkie](https://discuss.elastic.co/u/Pixarjunkie)\
**Replies:** 9\
**Last updated:** [July 5, 2018, 9:41pm UTC](https://discuss.elastic.co/t/logstash-sourceloader-no-configuration-found-in-the-configured-sources/138441 "2018-07-05T21:41:49Z")

</div>

I have a config file that was running alright until this morning. The contents are: input { file { path =\> "C:/Users/data/test.csv" start\_position =\> "beginning" sincedb\_path =\> "/dev/null" } } filter { …

---

## [Unable to login via LDAP if user password contains special chars](https://discuss.elastic.co/t/unable-to-login-via-ldap-if-user-password-contains-special-chars/77665)

<div class="topic-metadata">

**Author:** [@Matteo\_Fracassetti](https://discuss.elastic.co/u/Matteo_Fracassetti)\
**Replies:** 12\
**Last updated:** [March 8, 2017, 2:03pm UTC](https://discuss.elastic.co/t/unable-to-login-via-ldap-if-user-password-contains-special-chars/77665 "2017-03-08T14:03:39Z")

</div>

I'm experimenting with Elasticsearch and X-Pack, I'm using X-Pack in trial mode with no license, installed via RPM. I've installed a 2-node cluster on Oracle Linux 7.x, using Oracle jdk1.8.0\_121 ( localectl System L…

---

## [Impossible to create Repository for a snapshot : location \[...\] doesn't match any of the locations specified by path.repo because this setting is empty](https://discuss.elastic.co/t/impossible-to-create-repository-for-a-snapshot-location-doesnt-match-any-of-the-locations-specified-by-path-repo-because-this-setting-is-empty/110228)

<div class="topic-metadata">

**Author:** [@elastic\_mostafa](https://discuss.elastic.co/u/elastic_mostafa)\
**Replies:** 14\
**Last updated:** [December 18, 2017, 3:17pm UTC](https://discuss.elastic.co/t/impossible-to-create-repository-for-a-snapshot-location-doesnt-match-any-of-the-locations-specified-by-path-repo-because-this-setting-is-empty/110228 "2017-12-18T15:17:42Z")

</div>

Okey let me start from the beginning , I created this directory : /home/mostafa/public\_html/ES\_repository I added path.repo: \["/mount/backups"\] to the elasticsearch.yml a the end of file then I saved that file after…

---

## [Filebeat Cant connect: ERROR x509: cannot validate certificate for x.xx.xx.xxx because it doesn't contain any IP SANs](https://discuss.elastic.co/t/filebeat-cant-connect-error-x509-cannot-validate-certificate-for-x-xx-xx-xxx-because-it-doesnt-contain-any-ip-sans/127089)

<div class="topic-metadata">

**Author:** [@Peeyush\_Gupta](https://discuss.elastic.co/u/Peeyush_Gupta)\
**Replies:** 11\
**Last updated:** [April 12, 2018, 8:21am UTC](https://discuss.elastic.co/t/filebeat-cant-connect-error-x509-cannot-validate-certificate-for-x-xx-xx-xxx-because-it-doesnt-contain-any-ip-sans/127089 "2018-04-12T08:21:11Z")

</div>

Hi, I have been trying to connect filebeat to a cluster that has http encryption done, when I try to connect, I get this error: elasticsearch: https://xx.xx.xx.xx:9200... parse url... OK connection... parse hos…

---

## [Logstash status: Failed to start logstash](https://discuss.elastic.co/t/logstash-status-failed-to-start-logstash/216065)

<div class="topic-metadata">

**Author:** [@Ekta](https://discuss.elastic.co/u/Ekta)\
**Replies:** 9\
**Last updated:** [January 28, 2020, 3:37am UTC](https://discuss.elastic.co/t/logstash-status-failed-to-start-logstash/216065 "2020-01-28T03:37:53Z")

</div>

logstash failed to start. I am using logstash7 .2.0 Elasticsearch-7.2.0 Java-11.0.6 When I check the status after starting it shows Active:Failed. $: systemctl status logstash.service â logstash.service - logstas…

---

## [Kibana adds 2 hours to timestamp](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731)

<div class="topic-metadata">

**Author:** [@trenzalore](https://discuss.elastic.co/u/trenzalore)\
**Replies:** 18\
**Last updated:** [October 24, 2016, 1:58pm UTC](https://discuss.elastic.co/t/kibana-adds-2-hours-to-timestamp/63731 "2016-10-24T13:58:29Z")

</div>

Hi ! I know that this question comes back often but I didn't find a good answer for my problem. So I set up a cluster of 3 servers: Two are made up with the docker image sebp/elk and the kibana server is installed wi…

---

## [Sorting on a custom script field in Java](https://discuss.elastic.co/t/sorting-on-a-custom-script-field-in-java/10912)

<div class="topic-metadata">

**Author:** [@echin1999\_2](https://discuss.elastic.co/u/echin1999_2)\
**Replies:** 16\
**Last updated:** [July 29, 2014, 3:02am UTC](https://discuss.elastic.co/t/sorting-on-a-custom-script-field-in-java/10912 "2014-07-29T03:02:06Z")

</div>

Hi, I was wondering if someone could point me to some sample Java code that specifically shows how to sort on a custom script field. I see that the SearchRequestBuilder has a method called: addScriptFiel…

---

## [I get the error "No processor type exists with name \[attachment\]"](https://discuss.elastic.co/t/i-get-the-error-no-processor-type-exists-with-name-attachment/188935)

<div class="topic-metadata">

**Author:** [@FeizNouri](https://discuss.elastic.co/u/FeizNouri)\
**Replies:** 19\
**Last updated:** [July 8, 2019, 1:28pm UTC](https://discuss.elastic.co/t/i-get-the-error-no-processor-type-exists-with-name-attachment/188935 "2019-07-08T13:28:49Z")

</div>

i get { "error": { "root\_cause": \[ { "type": "parse\_exception", "reason": "No processor type exists with name \[attachment\]", "processor\_type": "attachment" } \], "type": "parse\_exception", "reason": "No process…

---

## [Elasticsearch always crashes with query aggregations](https://discuss.elastic.co/t/elasticsearch-always-crashes-with-query-aggregations/62482)

<div class="topic-metadata">

**Author:** [@willypol](https://discuss.elastic.co/u/willypol)\
**Replies:** 20\
**Last updated:** [October 16, 2016, 5:10pm UTC](https://discuss.elastic.co/t/elasticsearch-always-crashes-with-query-aggregations/62482 "2016-10-16T17:10:24Z")

</div>

Hello! We are integrating ES \[2.4.0\] with a new application. The application is distributed in an appliance with 32 CPUs and 64Gb of RAM. It collects different types of logs. In a normal installation we have 15Gb of da…

---

## [Why \_jsonparsefailure?](https://discuss.elastic.co/t/why-jsonparsefailure/175448)

<div class="topic-metadata">

**Author:** [@juandanielpujols](https://discuss.elastic.co/u/juandanielpujols)\
**Replies:** 9\
**Last updated:** [April 4, 2019, 8:34pm UTC](https://discuss.elastic.co/t/why-jsonparsefailure/175448 "2019-04-04T20:34:10Z")

</div>

Having \_jsonparsefailure, and json parser says messsage is good json. I have this configuration file: input { http\_poller { urls =\> { url =\> "https://urlhost:443/remote/core.executeQuery?queryId=###&:output=json" } …

---

## [Hot to send a data from logstash server to a remote elasticserach?](https://discuss.elastic.co/t/hot-to-send-a-data-from-logstash-server-to-a-remote-elasticserach/94668)

<div class="topic-metadata">

**Author:** [@kamalbeg](https://discuss.elastic.co/u/kamalbeg)\
**Replies:** 10\
**Last updated:** [July 29, 2017, 8:38am UTC](https://discuss.elastic.co/t/hot-to-send-a-data-from-logstash-server-to-a-remote-elasticserach/94668 "2017-07-29T08:38:05Z")

</div>

I have a server where I have installed logstash. I am trying to forward a log file from my Linux server to a remote elastic search server. What config do I need to do to achieve this? I have install ELK only 2 days ago. …

---

## [POST method http\_poller](https://discuss.elastic.co/t/post-method-http-poller/141940)

<div class="topic-metadata">

**Author:** [@m.sereda](https://discuss.elastic.co/u/m.sereda)\
**Replies:** 53\
**Last updated:** [August 3, 2018, 10:33am UTC](https://discuss.elastic.co/t/post-method-http-poller/141940 "2018-08-03T10:33:40Z")

</div>

Trying to make a POST method to login but smth is going wrong. To make a login I have to fill "login" and "password" poles which is in JSON. Where is a mistake? input { http\_poller { urls =\> { soap\_request …

---

## [How to search using boolean operators AND, OR or Not in dev tools?](https://discuss.elastic.co/t/how-to-search-using-boolean-operators-and-or-or-not-in-dev-tools/189485)

<div class="topic-metadata">

**Author:** [@pyerunka](https://discuss.elastic.co/u/pyerunka)\
**Replies:** 21\
**Last updated:** [July 16, 2019, 5:59am UTC](https://discuss.elastic.co/t/how-to-search-using-boolean-operators-and-or-or-not-in-dev-tools/189485 "2019-07-16T05:59:47Z")

</div>

Hello, Can anyone help me to use Boolean search in dev tools query? Thanks, Priyanka

---

## [Fail to get kibana](https://discuss.elastic.co/t/fail-to-get-kibana/223906)

<div class="topic-metadata">

**Author:** [@talaat](https://discuss.elastic.co/u/talaat)\
**Replies:** 12\
**Last updated:** [March 19, 2020, 11:27am UTC](https://discuss.elastic.co/t/fail-to-get-kibana/223906 "2020-03-19T11:27:49Z")

</div>

Dears I get this error messege when I trying to import the dashboard for winlogbeat in to kibana error connecting to Kibana: fail to get the Kibana version: HTTP GET request to http://x.y.z.a:5601/api/status fails: fai…

---

## [Exception caught on transport layer](https://discuss.elastic.co/t/exception-caught-on-transport-layer/113655)

<div class="topic-metadata">

**Author:** [@Koustav\_Chatterjee](https://discuss.elastic.co/u/Koustav_Chatterjee)\
**Replies:** 11\
**Last updated:** [January 1, 2018, 1:56pm UTC](https://discuss.elastic.co/t/exception-caught-on-transport-layer/113655 "2018-01-01T13:56:14Z")

</div>

I am using ElasticSearch 2.3 on ec2(ubuntu). I had run sudo apt-get update and upgrade.Then restart the box. When i start the ES,this is what i run into. \[2017-12-31 11:33:21,605\]\[WARN \]\[transport.netty \] \[Qua…

---

## [Ingesting JSON Data Samples w/ Logstash](https://discuss.elastic.co/t/ingesting-json-data-samples-w-logstash/275185)

<div class="topic-metadata">

**Author:** [@pkward](https://discuss.elastic.co/u/pkward)\
**Replies:** 33\
**Last updated:** [June 9, 2021, 9:57pm UTC](https://discuss.elastic.co/t/ingesting-json-data-samples-w-logstash/275185 "2021-06-09T21:57:10Z")

</div>

Hello, I'm trying to test a machine learning classifier in elasticsearch, but I am having a hard time ingesting my data. I've tried using JQ to stream the data via Bulk API, so now I'm ready to try Logstash which may be…

---

## [Issue help - snapshot creation failure](https://discuss.elastic.co/t/issue-help-snapshot-creation-failure/81059)

<div class="topic-metadata">

**Author:** [@Letian](https://discuss.elastic.co/u/Letian)\
**Replies:** 25\
**Last updated:** [April 19, 2017, 5:12pm UTC](https://discuss.elastic.co/t/issue-help-snapshot-creation-failure/81059 "2017-04-19T17:12:27Z")

</div>

Hi all, I've been trying to create the snapshot for the ES system. I have added the path.repo and restarted the services and it all looks fine. When I tried to create the snapshot like following curl -XPUT 'http://10.…

---

## [How to see the logs are shipped from filebeat to logstash](https://discuss.elastic.co/t/how-to-see-the-logs-are-shipped-from-filebeat-to-logstash/127792)

<div class="topic-metadata">

**Author:** [@Roshan\_r](https://discuss.elastic.co/u/Roshan_r)\
**Replies:** 9\
**Last updated:** [April 12, 2018, 2:01pm UTC](https://discuss.elastic.co/t/how-to-see-the-logs-are-shipped-from-filebeat-to-logstash/127792 "2018-04-12T14:01:37Z")

</div>

Hi All, I am using filebeat for the first time. How can i make sure that the actual logs are shipped to logstash from filebeat? How can i monitor that? i can see filebeat is running without any issues. I have enabled …

---

## [Filebeat multiline filter and unknown escape character](https://discuss.elastic.co/t/filebeat-multiline-filter-and-unknown-escape-character/40872)

<div class="topic-metadata">

**Author:** [@incogniro](https://discuss.elastic.co/u/incogniro)\
**Replies:** 10\
**Last updated:** [February 17, 2016, 7:57am UTC](https://discuss.elastic.co/t/filebeat-multiline-filter-and-unknown-escape-character/40872 "2016-02-17T07:57:33Z")

</div>

I'm configuring filebeat to multiline any line not containing a date in 3 formats as shown below in the configuration snippet. # Date with hyphen seperator. pattern: "^(19|20)\\d\\d(\[- /.\])(0\[1-9\]|1\[012\])\\2(0\[1-9…

---

## [Version 5 and Java not working](https://discuss.elastic.co/t/version-5-and-java-not-working/64589)

<div class="topic-metadata">

**Author:** [@Andrew\_Davis](https://discuss.elastic.co/u/Andrew_Davis)\
**Replies:** 10\
**Last updated:** [April 12, 2017, 11:49am UTC](https://discuss.elastic.co/t/version-5-and-java-not-working/64589 "2017-04-12T11:49:34Z")

</div>

Ok, i am looking at using ElasticSearch, via Java, for one of my applications, and have installed version 5.0.0 and have it running ok, in about 10 mins i have now copied, the Jar file down, into my test app, (netbeans…

---

## [No geo\_point fields logstash 6](https://discuss.elastic.co/t/no-geo-point-fields-logstash-6/111788)

<div class="topic-metadata">

**Author:** [@prophoto](https://discuss.elastic.co/u/prophoto)\
**Replies:** 27\
**Last updated:** [February 3, 2018, 12:28am UTC](https://discuss.elastic.co/t/no-geo-point-fields-logstash-6/111788 "2018-02-03T00:28:14Z")

</div>

No Compatible Fields: The "apache-access\_\*" index pattern does not contain any of the following field types: geo\_point Logstash geo config that worked fine for logstash 5.6 geoip { source =\> "clientip" target =\> …

---

## [Logstash backfilling two type of logs, problem!](https://discuss.elastic.co/t/logstash-backfilling-two-type-of-logs-problem/40646)

<div class="topic-metadata">

**Author:** [@gh0stid](https://discuss.elastic.co/u/gh0stid)\
**Replies:** 42\
**Last updated:** [February 20, 2016, 5:34am UTC](https://discuss.elastic.co/t/logstash-backfilling-two-type-of-logs-problem/40646 "2016-02-20T05:34:39Z")

</div>

Hello, peopleeeee ! sorry to disturb you with probably such an easy question for you, veteran... BUT ... im stuck, and I mean it... heres the situation, i need to backfill a few days back log from /var/log/network.log …

---

## [Logstash again is failing to create monitoring event](https://discuss.elastic.co/t/logstash-again-is-failing-to-create-monitoring-event/85147)

<div class="topic-metadata">

**Author:** [@seriv](https://discuss.elastic.co/u/seriv)\
**Replies:** 13\
**Last updated:** [June 6, 2017, 10:21pm UTC](https://discuss.elastic.co/t/logstash-again-is-failing-to-create-monitoring-event/85147 "2017-06-06T22:21:52Z")

</div>

Hi, I have elastic-5.4.0 (elasticsearch, logstash, and kibana) all with x-pack, and trying to get the last piece working: getting some events from logstash. Started with --log.level debug, I see the following in logsta…

---

## [Problem when indexing nested object (Elasticsearch 5.6)](https://discuss.elastic.co/t/problem-when-indexing-nested-object-elasticsearch-5-6/116177)

<div class="topic-metadata">

**Author:** [@Phongsatorn.P](https://discuss.elastic.co/u/Phongsatorn.P)\
**Replies:** 19\
**Last updated:** [January 23, 2018, 8:01am UTC](https://discuss.elastic.co/t/problem-when-indexing-nested-object-elasticsearch-5-6/116177 "2018-01-23T08:01:48Z")

</div>

Hi there, I have some problem when i want to index (by using cURL) nested object , assume i have to indices (restaurant\_info and restaurant\_payment) both two indices have nested object. But problem that occured was nest…

---

## [Mutual tls/ssl on elasticsearch](https://discuss.elastic.co/t/mutual-tls-ssl-on-elasticsearch/197768)

<div class="topic-metadata">

**Author:** [@SukeshGupta](https://discuss.elastic.co/u/SukeshGupta)\
**Replies:** 24\
**Last updated:** [September 10, 2019, 9:37am UTC](https://discuss.elastic.co/t/mutual-tls-ssl-on-elasticsearch/197768 "2019-09-10T09:37:43Z")

</div>

Hi, I want to know how to enable mutual tls/ssl on elastic. I have added the below lines in my elastic.yml file : xpack.security.enabled: true xpack.security.http.ssl.enabled: true xpack.security.http.ssl.key: certs/de…

---

## [Condition with decode\_json\_fields processor](https://discuss.elastic.co/t/condition-with-decode-json-fields-processor/115093)

<div class="topic-metadata">

**Author:** [@jochenchrist](https://discuss.elastic.co/u/jochenchrist)\
**Replies:** 9\
**Last updated:** [January 16, 2018, 6:18pm UTC](https://discuss.elastic.co/t/condition-with-decode-json-fields-processor/115093 "2018-01-16T18:18:46Z")

</div>

Hi, I try to collect docker logs with filebeats 6.1. The application logs are written as JSON, which I want to decode with decode\_json\_fields processor. Spring Boot's Bootstrapping also writes some plain log messages,…

---

## [Logstash event ruby code](https://discuss.elastic.co/t/logstash-event-ruby-code/108683)

<div class="topic-metadata">

**Author:** [@hsiuming](https://discuss.elastic.co/u/hsiuming)\
**Replies:** 12\
**Last updated:** [November 28, 2017, 8:44am UTC](https://discuss.elastic.co/t/logstash-event-ruby-code/108683 "2017-11-28T08:44:08Z")

</div>

Hello We now set our own field by ruby code in logstash. There are three Binary fields. We have two question about: (1) The logstash setting code is: event.set('\[Binary1\]', event.get('\[event\_data\]\[Binary\]')\[0..7\]) e…

---

## [How to create and set default Index in kibana 6.1 using Python](https://discuss.elastic.co/t/how-to-create-and-set-default-index-in-kibana-6-1-using-python/119175)

<div class="topic-metadata">

**Author:** [@Sandeep\_Sarkar](https://discuss.elastic.co/u/Sandeep_Sarkar)\
**Replies:** 12\
**Last updated:** [March 15, 2018, 3:22am UTC](https://discuss.elastic.co/t/how-to-create-and-set-default-index-in-kibana-6-1-using-python/119175 "2018-03-15T03:22:31Z")

</div>

Hi @all, I would like to create and set default index in Kibana 6.1 using Python. How to achieve that? Thanks, Sandeep Sarkar

---

## [How i search firstname + lastname in elasticsearch](https://discuss.elastic.co/t/how-i-search-firstname-lastname-in-elasticsearch/181807)

<div class="topic-metadata">

**Author:** [@arunkvinam](https://discuss.elastic.co/u/arunkvinam)\
**Replies:** 15\
**Last updated:** [May 21, 2019, 9:47am UTC](https://discuss.elastic.co/t/how-i-search-firstname-lastname-in-elasticsearch/181807 "2019-05-21T09:47:44Z")

</div>

Hi Team, firstname ,middlename and lastname are seperate fields in my index . But i can't search firstname + middlename+lastname. In mysql I used concat function .But Elasticsearch I do not find any option to do conc…

---

## [\[SOLVED\] The filter plugin mutate-convert doesn't work in 5.0](https://discuss.elastic.co/t/solved-the-filter-plugin-mutate-convert-doesnt-work-in-5-0/65496)

<div class="topic-metadata">

**Author:** [@tileaga](https://discuss.elastic.co/u/tileaga)\
**Replies:** 16\
**Last updated:** [November 11, 2016, 1:21pm UTC](https://discuss.elastic.co/t/solved-the-filter-plugin-mutate-convert-doesnt-work-in-5-0/65496 "2016-11-11T13:21:31Z")

</div>

In my logstash config I have something like this: mutate { add\_field =\> { "\[%{name}\]\[long\]" =\> "%{valueLong}" } remove\_field =\> \[valueLong\] convert =\> \["\[%{name}\]\[long\]", "in…

---

## [Gather Syslogs from a router](https://discuss.elastic.co/t/gather-syslogs-from-a-router/45338)

<div class="topic-metadata">

**Author:** [@brayndasilva](https://discuss.elastic.co/u/brayndasilva)\
**Replies:** 12\
**Last updated:** [March 31, 2016, 12:27pm UTC](https://discuss.elastic.co/t/gather-syslogs-from-a-router/45338 "2016-03-31T12:27:55Z")

</div>

Hi, How could I set up my router to send its Syslogs to Logstash? I already have my ELK server set up completely and got a Client Server that is successfully sending its Syslogs to Logstash where I can visualize it i…

---

## [Create geo\_point from nested coordinates](https://discuss.elastic.co/t/create-geo-point-from-nested-coordinates/60835)

<div class="topic-metadata">

**Author:** [@Crai](https://discuss.elastic.co/u/Crai)\
**Replies:** 12\
**Last updated:** [September 21, 2016, 11:16pm UTC](https://discuss.elastic.co/t/create-geo-point-from-nested-coordinates/60835 "2016-09-21T23:16:39Z")

</div>

I am trying to create a geo\_point field to add coords using the http poller to pull some data in json format. so the json is coming in a format like this. Multiple JSON documents representing each item and it's proper…

---

## [Feature Request Flowbeat!](https://discuss.elastic.co/t/feature-request-flowbeat/1957)

<div class="topic-metadata">

**Author:** [@Steve\_Kelley](https://discuss.elastic.co/u/Steve_Kelley)\
**Replies:** 11\
**Last updated:** [June 28, 2017, 5:30am UTC](https://discuss.elastic.co/t/feature-request-flowbeat/1957 "2017-06-28T05:30:01Z")

</div>

Love the packet beat analyzer! Is there future plans for analyzing flows? IE: S-Flow, Netflow?

---

## [Embedding dashboard in website with dynamic filter param](https://discuss.elastic.co/t/embedding-dashboard-in-website-with-dynamic-filter-param/120510)

<div class="topic-metadata">

**Author:** [@agonzalez](https://discuss.elastic.co/u/agonzalez)\
**Replies:** 9\
**Last updated:** [February 22, 2018, 12:31am UTC](https://discuss.elastic.co/t/embedding-dashboard-in-website-with-dynamic-filter-param/120510 "2018-02-22T00:31:27Z")

</div>

I want to embbed dashboard on my website: i need to know how to pass URL filters dynamically so i can show each customer only their dashboard data based in customer\_id field or other fields. Also how to remove the…

---

## [Error: Invalid string. Length must be a multiple of 4](https://discuss.elastic.co/t/error-invalid-string-length-must-be-a-multiple-of-4/293201)

<div class="topic-metadata">

**Author:** [@mohantychandra](https://discuss.elastic.co/u/mohantychandra)\
**Replies:** 13\
**Last updated:** [January 19, 2022, 10:56am UTC](https://discuss.elastic.co/t/error-invalid-string-length-must-be-a-multiple-of-4/293201 "2022-01-19T10:56:11Z")

</div>

Hi Can anyone help to resolve the issue, Any comment is much appreciated. The issue and log is given below. Invalid string. Length must be a multiple of 4 Error: Invalid string. Length must be a multiple of 4

---

## [Default index pattern goes missing](https://discuss.elastic.co/t/default-index-pattern-goes-missing/110158)

<div class="topic-metadata">

**Author:** [@rs\_ela](https://discuss.elastic.co/u/rs_ela)\
**Replies:** 12\
**Last updated:** [December 14, 2017, 11:07am UTC](https://discuss.elastic.co/t/default-index-pattern-goes-missing/110158 "2017-12-14T11:07:01Z")

</div>

Hi all. Anyone also having this issue where ocassionally the default index pattern is no longer default and Kibana needs user to "star" some pattern once again? It happens on my instance every once in a while. Can't come…

---

## [Filebeat couldn't start](https://discuss.elastic.co/t/filebeat-couldnt-start/136046)

<div class="topic-metadata">

**Author:** [@asalma](https://discuss.elastic.co/u/asalma)\
**Replies:** 13\
**Last updated:** [July 5, 2018, 9:56am UTC](https://discuss.elastic.co/t/filebeat-couldnt-start/136046 "2018-07-05T09:56:59Z")

</div>

Hi, I did this configuration on filebeat.yml but I had this error when I started it : - type: log enabled: true paths: - /var/log/network/FWEquin\_WAN\_R03-01M.log fields: log\_type: fortigate - type: log …

---

## [Initialization elastricsearch fail](https://discuss.elastic.co/t/initialization-elastricsearch-fail/26282)

<div class="topic-metadata">

**Author:** [@satimis](https://discuss.elastic.co/u/satimis)\
**Replies:** 14\
**Last updated:** [July 27, 2015, 8:23pm UTC](https://discuss.elastic.co/t/initialization-elastricsearch-fail/26282 "2015-07-27T20:23:24Z")

</div>

Hi all, I followed; How To Install Elasticsearch on an Ubuntu VPS https://www.digitalocean.com/community/tutorials/how-to-install-elasticsearch-on-an-ubuntu-vps Coming to; Test your Elasticsearch install Performed; …

---

## [Repository](https://discuss.elastic.co/t/repository/37948)

<div class="topic-metadata">

**Author:** [@Hilal](https://discuss.elastic.co/u/Hilal)\
**Replies:** 13\
**Last updated:** [July 13, 2016, 11:09am UTC](https://discuss.elastic.co/t/repository/37948 "2016-07-13T11:09:28Z")

</div>

Hi, I am trying to snapshot and restore module in elasticsearch but ı have a problem. I am using marvel plugin. My repository codes: PUT /\_snapshot/my\_backup/ { "type": "fs", "settings": { "location":…

---

## [Can not get run Elasticsearch 6 on my MAC](https://discuss.elastic.co/t/can-not-get-run-elasticsearch-6-on-my-mac/301707)

<div class="topic-metadata">

**Author:** [@Sajjad\_Murtaza](https://discuss.elastic.co/u/Sajjad_Murtaza)\
**Replies:** 16\
**Last updated:** [June 1, 2022, 3:50pm UTC](https://discuss.elastic.co/t/can-not-get-run-elasticsearch-6-on-my-mac/301707 "2022-06-01T15:50:55Z")

</div>

Hi all, I can not get run Elasticsearch 6 on my MAC ➜ ~ brew services list Name Status User File dbus none …

[Previous page](https://discuss.elastic.co/top.md?page=22&per_page=50&period=all)

[Next page](https://discuss.elastic.co/top.md?page=24&per_page=50&period=all)
